Ahmed Adel Ali, Ahmed Waleed Ali
Faculty of Computing and Information Technology, King Abdulaziz University, Rabigh, Jeddah 25729, Saudi Arabia.
Sensors (Basel). 2019 Aug 23;19(17):3663. doi: 10.3390/s19173663.
Internet of Thing (IoT) is the most emerging technology in which all the objects in the real world can use the Internet to communicate with each other as parts of a single unified system. This eventually leads to the development of many smart applications such as smart cities, smart homes, smart healthcare, smart transportation, etc. Due to the fact that the IoT devices have limited resources, the cybersecurity approaches that relied on complex and long processing cryptography are not a good fit for these constrained devices. Moreover, the current IoT systems experience critical security vulnerabilities that include identifying which devices were affected, what data or services were accessed or compromised, and which users were impacted. The cybersecurity challenge in IoT systems is to find a solution for handling the identity of the user, things/objects and devices in a secure manner. This paper proposes an effective multifactor authentication (CMA) solution based on robust combiners of the hash functions implemented in the IoT devices. The proposed CMA solution mitigates the authentication vulnerabilities of IoT and defends against several types of attacks. Also, it achieves multi-property robustness and preserves the collision-resistance, the pseudo-randomness, the message authentication code, and the one-wayness. It also ensures the integrity, authenticity and availability of sensed data for the legitimate IoT devices. The simulation results show that CMA outperforms the TOTP in term of the authentication failure rate. Moreover, the evaluation of CMA shows an acceptable QoS measurement in terms of computation time overhead, throughput, and packet loss ratio.
物联网(IoT)是最具创新性的技术,在这一技术体系中,现实世界中的所有物体都能够作为一个统一系统的组成部分,通过互联网实现相互通信。这最终催生了许多智能应用的发展,如智慧城市、智能家居、智能医疗、智能交通等。由于物联网设备资源有限,依赖复杂且耗时的加密技术的网络安全方法并不适用于这些受限设备。此外,当前的物联网系统存在严重的安全漏洞,包括确定哪些设备受到影响、哪些数据或服务被访问或泄露,以及哪些用户受到影响。物联网系统中的网络安全挑战在于找到一种安全处理用户、物品/对象和设备身份的解决方案。本文提出了一种基于物联网设备中实现的哈希函数的强大组合器的有效多因素认证(CMA)解决方案。所提出的CMA解决方案减轻了物联网的认证漏洞,并抵御了多种类型的攻击。此外,它实现了多属性鲁棒性,并保留了抗碰撞性、伪随机性、消息认证码和单向性。它还确保了合法物联网设备所感知数据的完整性、真实性和可用性。仿真结果表明,在认证失败率方面,CMA优于时间同步令牌(TOTP)。此外,对CMA的评估在计算时间开销、吞吐量和丢包率方面显示出可接受的服务质量(QoS)测量结果。